CISOs face higher stakes as regulators crack down on security failures

November 6, 2023 Regulators are holding chief information security officers (CISOs) liable for the cybersecurity challenges they or their companies face, as evidenced by the SEC charges against SolarWinds and its top security executive, Timothy Brown.

The SEC’s complaint alleges that SolarWinds misled investors about the state of the company’s cyber defenses in the years leading up to a massive 2020 Russian cyberattack. The charges come a few months after a jury found former Uber security executive Joe Sullivan guilty of obstructing an active Federal Trade Commission investigation into Uber’s security practices and concealing a 2016 data breach.

These cases signal a new willingness on the part of regulators to hold CISOs accountable for cybersecurity failures, which is raising concerns among security executives. Some worry that the new SEC cyber disclosure rules, which go into effect next month, could lead to more frequent charges against CISOs, as they will require publicly traded companies to disclose material cyber incidents within four business days and share details about their internal cybersecurity strategies each year.

CISOs are now worried that any statements they make early in their incident response, or even in the years before an attack, could lead to legal problems years later, as it has for SolarWinds.

In an op-ed, Sullivan argued that the SolarWinds’ charges will lead “the private sector to become afraid to work closely with the government” after an attack.

Prospective security leaders may also be discouraged from taking on top roles in the wake of the SolarWinds and Sullivan cases, said Michael Sikorski, CTO and VP of engineering for Palo Alto Networks’ threat intelligence team.

The sources for this piece include an article in Axios.

Top Stories

Related Articles

March 5, 2026 Check Point Software on Wednesday launched a dedicated Canada data region for its CloudGuard Web Application Firewall more...

March 5, 2026 A small development company in Mexico says a compromised Google Cloud API key triggered more than $82,000 more...

March 2, 2026 Thousands of exposed Google Cloud API keys can authenticate to Gemini endpoints when the Generative Language API more...

March 2, 2026 Threat actors are exploiting Microsoft Entra ID through Open Authorization (OAuth) consent abuse, using seemingly legitimate third-party more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn